Skill
Parameterize DB queries
Always pass values to a query engine (SQL, Cypher, etc.) as bound PARAMETERS, never by string- interpolating them into the query text. String interpolation breaks on embedded quotes, lists, and special characters (syntax errors), is an injection vector, and — when the binding is passed as keyword args — can collide with the driver's own method signature (a param named self/id/type) and silently misbehave. Use a params dict/object. USE WHEN building any SQL/Cypher/query string, especially one containing quotes, lists, user/graph-derived values, or a reserved-word key.
Primitives inside (6)
bind-values-never-interpolatedisciplineQuery TEXT is static; VALUES travel as bound parameters ($name/? placeholders + a params dict/tuple). Never f-string/format a value into SQL/Cypher — quotes, None, lists, and injection all break it.
When: Building ANY SQL/Cypher/query string, especially one containing quotes, lists, None/null, or user/graph/file-derived values.
identifiers-need-allowlist-not-paramsgotcha-fixBinding covers VALUES only: `FROM ?`, `MATCH (n:$lbl)`, `-[r:$t]->` are syntax errors. Table/column names, labels, and rel types must come from an ALLOWLIST — the residual injection surface.
When: A query needs a dynamic table/column name, node label, or relationship type.
json-body-param-binding-transportdisciplineBinding must survive the transport: build HTTP query bodies ({"statement":..., "parameters":{...}}) with json.dumps, never by f-string/shell interpolation — or you reintroduce the same bug one layer up.
When: Sending a parameterized query to a DB over an HTTP API (e.g. Neo4j query/v2 or tx/commit) from a script or shell.
like-wildcard-pattern-escapegotcha-fixBinding stops query-TEXT injection but %/_ inside a bound LIKE parameter still act as wildcards (pattern injection) — escape or validate LIKE inputs as a separate step.
When: A user/derived value is bound into a LIKE (or STARTS WITH-style pattern) predicate.
literalstring-type-guardfailsafeDrivers typing query text as LiteralString (PEP 675, e.g. neo4j) let a type-checker flag interpolated query strings automatically — free static enforcement of bind-don't-interpolate.
When: A Python codebase with a type-checker (mypy/pyright) using a driver whose query argument is typed LiteralString.
sql-in-list-placeholder-expansionquery-shapeSQL cannot bind a list to one IN placeholder (`IN ?` errors); expand placeholders from the count — "IN (" + ",".join("?"*len(vals)) + ")" — still binding every value. Cypher takes $list natively.
When: A SQL WHERE ... IN clause over a runtime list of values.
Get the whole skill
All 6 primitives of this skill as one package, with the order to apply them.
Buy only the primitives you need
Each primitive is 1 credit (≈ €0.10). Pick them from the list above — the button is next to each one.
Upgrade your own skill
Paste your skill; we pick the 5 primitives from the shelf that fit it best, as one bundle for 5 credits (≈ €0.50).
Upgrade my skillNeighbour skills
Skills whose primitives are closest to this one (bge-m3 similarity):